This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2174 | CleverTap Cordova plugin vulnerable to Cross-site Scripting |
Github GHSA |
GHSA-x2ph-qqwm-9cc6 | CleverTap Cordova plugin vulnerable to Cross-site Scripting |
Wed, 24 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them. | CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them. |
| References |
|
Wed, 30 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-09-24T14:10:13.526Z
Reserved: 2023-05-03T22:24:15.786Z
Link: CVE-2023-2507
Updated: 2024-08-02T06:26:08.920Z
Status : Modified
Published: 2023-07-15T19:15:09.527
Modified: 2025-09-24T14:15:46.170
Link: CVE-2023-2507
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA